Global Data Protection Standard verified_user GDPR, CCPA & DIFC Compliant security ISO/IEC 27001 Certified Architecture

Global Client Privacy Policy & Data Governance Charter

How Nova Spectrum Pro collects, isolates, encrypts, processes, and safeguards institutional, corporate, and individual wealth telemetry and personal asset data across sovereign execution layers.

Effective Date Nov 01, 2024
Charter Version v5.1 Institutional
Jurisdictional Scopes EU / UK / US / DIFC
Data Custody Level Zero-Knowledge MPC
Clause 1.0 REG-FID-2024

Scope & Quantitative Fiduciary Duty

Nova Spectrum Pro Inc., operating alongside its international branches, execution conduits, and sovereign capital vehicles (collectively, "Nova Spectrum Pro", "the Platform", "we", or "us"), treats data privacy as an uncompromisable fiduciary duty. Our systematic trading engine, machine learning portfolio models, and institutional prime interfaces operate under high-entropy security mandates.

This Policy governs the processing of data collected across all Nova Spectrum Pro execution terminals, Client Portals, algorithmic API bridges (FIX 4.4 / REST / WebSocket telemetry), institutional consultation desks, and institutional investor onboarding channels.

verified
Strict Commercial Non-Monetization Pledge

Nova Spectrum Pro will NEVER sell, lease, syndicate, license, or barter your personal records, trading telemetry, asset valuations, order routing vectors, or proprietary alpha configurations to data brokers, high-frequency predatory desks, or marketing aggregates.

Clause 2.0 DATA-TAXONOMY

Categories of Information Collected

In delivering ultra-low-latency quant routing, algorithmic rebalancing, and compliant custodial clearance, we gather distinct data classes strictly proportionate to regulatory necessity and execution performance:

badge Identity & KYC Verification
  • Government-issued biometric passports and national IDs
  • Corporate Articles, Certificate of Incumbency, and LEI codes
  • Ultimate Beneficial Ownership (UBO) declarations (>10% equity)
  • Proof of physical sovereign tax domicile
account_balance Custody & Financial Credentials
  • Tier-1 Prime Broker routing coordinates and SWIFT BIC
  • Qualified Purchaser & Accredited Investor verification
  • Source of Wealth (SoW) and Source of Funds (SoF) proofs
  • Risk tolerance profiles and volatility drawdown mandates
terminal Algorithmic Telemetry & Logs
  • FIX Protocol order messages, cancels, and executions
  • Sub-millisecond connection latencies & packet timestamps
  • API token authentications and IP whitelist binds
  • Hardware MAC addresses and browser crypt-fingerprints
encrypted Cryptographic Vault Metadata
  • Multi-Party Computation (MPC) partial share fingerprints
  • Hardware Security Module (HSM) session authorizations
  • Time-based One-Time Password (TOTP) seed rotation logs
  • Deterministic public routing addresses
Clause 3.0 GDPR-ART-6

Purpose & Legal Basis of Processing

Under Article 6 of the General Data Protection Regulation (GDPR) and reciprocal global frameworks, each computational operation on client data rests upon explicit lawful foundations:

1. Execution of Wealth Mandate Contract

Continuous portfolio optimization, order routing, and rebalancing calculation.

Contractual Necessity
2. International Anti-Money Laundering (AML) Compliance

OFAC, EU, UN, and DFSA screening, sanction checks, and STR filings.

Legal Obligation
3. Anomaly & Sybil Attack Prevention

Telemetry-driven firewall analytics, rate-limiting, and distributed credential defense.

Legitimate Interest
Clause 4.0 CRYPTO-ARCH

Cryptographic Storage & Zero-Trust Protocol

Nova Spectrum Pro enforces a zero-trust, defense-in-depth posture across all computational nodes. Identity data, API keys, and financial credentials are cryptographically isolated from Internet-exposed execution nodes.

Zero-Trust Key Management Lifecycle Air-Gapped HSM Operational
transit_enterexit

Transit Shield

TLS 1.3 / mTLS mandatory with Perfect Forward Secrecy (PFS)

lock_reset

Rest Encryption

AES-256-GCM cipher with customer-dedicated envelope encryption

hub

MPC Sharding

Threshold Signature Schemes (TSS 2-of-3) eliminating single private keys

Internal engineers have no mechanical access to clear-text trading models, private cryptographic keys, or unmasked investor credentials. All administrative interactions require dual-custody authorization within hardware-fenced enclave compute modules.

Clause 5.0 REL-DISCLOSE

Disclosure to Tier-1 Custodians & Authorities

We transmit strictly essential data payloads to authorized institutional counterparties for order clearing, settlement, and statutory governance:

Entity Category Data Shared Jurisdictions Safeguards
Tier-1 Custodian Banks LEI, Account Numbers, Settlement Vectors CH, UK, US, SG Encrypted Direct Lease Line
Statutory Regulators (FINMA, FCA, SEC) Audit Trails, Suspicious Activity Reports (STR) Global Accord Signed Diplomatic Relays
AML / Sanctions Screening Desks Names, Date of Birth, Sovereign Tax IDs EU / US Tokenized Hash Matching
Low-Latency Optical Networks Anonymized FIX execution signals LD4, NY4, TY3 Zero Identity Metadata
Clause 6.0 CROSS-BORDER

International Data Transfers & Cross-Border Relays

Given our continuous 24/7 algorithmic routing across global financial exchanges (New York, London, Zurich, Tokyo, Dubai), client data may be processed outside your home nation.

Where cross-border transfers occur out of the European Economic Area (EEA), United Kingdom, or Switzerland, Nova Spectrum Pro implements:

  • Standard Contractual Clauses (SCCs) ratified by the European Commission, supplemented by comprehensive Transfer Impact Assessments (TIAs).
  • Sovereign Data Fencing: European client identity vaults are physically anchored within Tier-4 data vaults in Frankfurt and Zurich.
  • UK International Data Transfer Addendum satisfying ICO specifications.
Clause 7.0 CLIENT-RIGHTS

Global Client Data Rights (GDPR & CCPA SLA)

Institutional allocators, corporate signers, and private investors retain unalienable jurisdictional control over their sovereign data profile:

Right to Erasure ("Forget") SLA < 30 Days

Purge of non-statutory records across all active compute instances upon account closure, subject to 5-year anti-money laundering statutory hold limits.

Right to Portability Instant Export

Direct export of trade histories, capital telemetry, and verification logs in machine-readable JSON or signed ISO 20022 XML formats.

Right of Rectification SLA < 48 Hours

Rapid remediation of corporate governance, beneficial ownership percentages, or updated financial disclosures via your dedicated desk.

Right to Object / Restrict Real-Time Switch

Immediate cessation of optional performance analytics telemetry and quantitative model profiling.

Clause 8.0 TELEMETRY-SWITCH

Cookie Policy & Algorithmic Telemetry Controls

We reject intrusive third-party commercial pixels, social media ad scrapers, or affiliate tracers. Telemetry is gathered exclusively for security integrity, latency optimization, and terminal state persistence.

Real-Time Telemetry Permissions

Strictly Necessary & Execution Session Tokens

Required for cryptographic authentication, FIX API sessions, and load balancing.

Locked Always-On

Sub-Millisecond Latency Diagnostics

Transmits anonymous network packet jitter statistics back to edge data centers.

Predictive Yield Interface Profiling

Caches localized dashboard views based on your past asset allocations.

Status: Hardware Token Synchronized
Clause 9.0 RETENTION-SHRED

Data Retention Schedules & Secure Shredding

Data is stored strictly for the duration necessary to satisfy quantitative fiduciary mandates and mandatory financial regulatory books-and-records periods:

• Statutory Financial Books (7 Years): Trade settlement tickets, capital receipts, SWIFT confirmation logs, and tax statements (pursuant to SEC Rule 17a-4 and Swiss CO Art. 958f).

• AML Identification Dossiers (5 Years post-termination): Stored in tamper-proof WORM (Write Once, Read Many) cloud-storage modules.

• Volatile Telemetry Records (90 Days): Micro-latency captures, IP logs, and unauthenticated packet inspection records are continuously shredded using cryptographic zeroization.

Clause 10.0 DPO-DISPUTE

DPO Contact & Supervisory Authority Inquiries

Should you wish to file a formal subject access request, revoke consent, or question algorithmic data handling protocols, contact our lead Data Protection Officer directly:

Direct Dispatch dpo@novaspectrumpro.com
Secure Regulatory Escalation compliance-intl@novaspectrumpro.com
Physical Service of Legal Process One Financial Center, 42nd Floor, Attn: DPO Legal Team, New York, NY 10005, United States

EEA clients additionally maintain the unconditional legal prerogative to file an inquiry or grievance with their regional data protection authority (e.g., the Irish Data Protection Commission or the German Federal Commissioner for Data Protection and Freedom of Information BfDI).

Sovereign Architecture

Institutional Trust & Cryptographic Defense

Four foundational technical pillars insulating all client transactions and data assets.

dns

Tier-4 Sovereign Vaults

Air-gapped compute facilities in Zurich, Frankfurt, and Secaucus with biometric perimeter gates and EMP-shielding.

memory

FIPS 140-2 Level 3 HSM

Execution authorizations execute within tamper-responsive hardware modules that zeroize upon structural breach.

key

End-to-End PGP Relays

Client reporting, statements, and high-frequency trade tickets signed deterministically with public key cryptography.

verified

SOC 2 Type II Continuous

Year-round third-party audits confirming zero non-conformities across confidentiality, availability, and privacy controls.

Institutional Security Desk

Require a Custom Data Protection Agreement (DPA)?

Sovereign wealth funds, family offices, and Tier-1 institutional clients can execute tailored bilateral DPAs with bespoke jurisdictional routing stipulations.